CVE-2026-3844

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if "Host Files Locally - Gravatars" is enabled, which is disabled by default.

Published 26 Aug 2026Updated 26 Aug 2026121 sources
CVSS 9.8 CRITICALPoC CANDIDATE

What happened

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if "Host Files Locally - Gravatars" is enabled, which is disabled by default.

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
CVE-Intel · Alevtinka19/CVE-2026-3844ExploitPHPCRITICALDeferred★ 0⑂ 0EPSS 27.70%CVE data: NISTCode indexedUpdated 26 Aug 2026Alevtinka192026-08-26CandidateCVE-Intel · AnggaTechI/CVE-2026-3844CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with multi-threading.RCEPythonCRITICALDeferred★ 2⑂ 0EPSS 27.70%CVE data: NISTCode indexedUpdated 14 Aug 2026AnggaTechI2026-08-08CandidateCVE-Intel · tausifzaman/CVE-2026-3844PoC exploit for CVE-2026-3844, a critical unauthenticated file upload vulnerability in the WordPress Breeze plugin leading to RCE.RCEPythonCRITICALDeferred★ 3⑂ 0EPSS 27.70%CVE data: NISTCode indexedUpdated 24 Jul 2026Tags: automation, cve, cve-2026-3844, exploit, hacking-script, hacking-tool, poctausifzaman2026-04-24CandidateCVE-Intel · dinosn/CVE-2026-3844CVE-2026-3844: Breeze Cache <= 2.4.4 Unauthenticated Arbitrary File Upload to RCE (CVSS 9.8)RCEPythonCRITICALDeferred★ 5⑂ 1EPSS 27.70%CVE data: NISTCode indexedUpdated 8 Jul 2026dinosn2026-04-25CandidateCVE-Intel · Dhananjayasj/CVE-2026-3844-Breeze-Cache-WordPress-Plugin-Remote-Code-ExecutionRCEPythonCRITICALDeferred★ 0⑂ 0EPSS 27.70%CVE data: NISTCode indexedUpdated 6 Jun 2026Dhananjayasj2026-06-06CandidateCVE-Intel · 0xgh057r3c0n/CVE-2026-3844WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File UploadExploitPythonCRITICALDeferred★ 1⑂ 1EPSS 27.70%CVE data: NISTCode indexedUpdated 27 May 20260xgh057r3c0n2026-04-24CandidateCVE-Intel · rootdirective-sec/CVE-2026-3844-LabExploitPythonCRITICALDeferred★ 0⑂ 1EPSS 27.70%CVE data: NISTCode indexedUpdated 15 May 2026rootdirective-sec2026-05-08CandidateCVE-Intel · halilkirazkaya/CVE-2026-3844CVE-2026-3844 — Breeze Cache Plugin RCE ExploitRCEPythonCRITICALDeferred★ 4⑂ 0EPSS 27.70%CVE data: NISTCode indexedUpdated 9 May 2026Tags: breeze, cve-2026-3844, exploit, wordpress, wordpress-pluginhalilkirazkaya2026-04-30Candidate